< ciso
brief />
Tag Banner

All news with #security awareness tag

231 articles · page 3 of 12

NCSC Warns of AI-Driven Patch Wave and Vulnerabilities

🛡️ The NCSC has warned UK organisations to prepare for a coming "patch wave" as vendors adopt powerful AI tools to discover and fix software vulnerabilities. CTO Ollie Whitehouse urged teams to prioritise external attack surfaces, enable automatic updates and hot patching where safe, and follow the NCSC's Vulnerability Management guidance. He cautioned that patching alone isn't enough for unsupported legacy systems and recommended replacing or restoring out-of-support technologies. The alert also notes potential US moves by CISA to shorten patch deadlines and industry concerns about operational readiness.
read more →

Webinar: Why MSPs Must Rethink Security and Backup

🔒 BleepingComputer and Kaseya will host a live webinar on May 14, 2026 at 2:00 PM EDT examining how modern attacks — led by AI-driven phishing and brand impersonation — are outpacing traditional defenses. The session explains why many MSPs segregate security and backup functions, creating gaps that threat actors exploit after initial compromise. Attendees will learn how to combine prevention, detection, and rapid recovery with SaaS backups and a robust BCDR strategy to minimize downtime and data loss.
read more →

Top Sales Challenges Costing MSPs Cybersecurity Revenue

🔍 The article identifies five go-to-market barriers that prevent managed service providers (MSPs) from converting growing cybersecurity demand into predictable revenue. It argues many MSPs emphasize technical findings and frameworks rather than translating risks into business outcomes, leaving security positioned as a cost rather than a strategic investment. Cynomi's GTM Academy Complete Sales Kit is presented as a practical, operator-led playbook to align sales and technical teams, quantify ROI, and expand existing accounts through targeted discovery, scoring, and playbooks.
read more →

Only 34% of Cyber Pros Plan to Stay With Employers

🔍Only 34% of cybersecurity professionals plan to remain with their current employer, according to a survey of 500 respondents by IANS and Artico Search. The report finds that flexible work models, visible leadership support, and structured career development influence retention more than absolute pay. Hybrid schedules, mentorship, and modern tooling help reduce burnout and turnover.
read more →

Cyber Threat Literacy Tops Global People Risks 2026

🛡️ Marsh's 2026 People Risks report, compiled from interviews with over 4,500 HR and risk professionals across 26 markets, finds cyber-threat literacy is the top global people risk, with technological change, tech skills shortages and AI-related mindset barriers also ranking highly. The report highlights mishandling of data and low employee security awareness as persistent threats that can increase exposure to breaches and reputational damage. Marsh recommends reframing cyber risk to cover OT, HR and third-party systems, recruiting cyber talent, building a cyber-centric culture, reducing fatigue, and ensuring human oversight with robust governance and insurance cover.
read more →

Eight Best Practices for CISOs Conducting Risk Reviews

📋 This blog by Rico Mariani outlines eight practical best practices for CISOs conducting risk reviews, focusing on identifying assets, applications, and access controls to shape review scope and priorities. It emphasizes good quality authentication (tokens and issuers like Microsoft Entra), robust authorization, network isolation, detection, and auditing to enable proactive security. The post also highlights commonly overlooked areas such as backups, support, and development systems to ensure comprehensive risk coverage.
read more →

Most Cybersecurity Staff Feel Undervalued and Underpaid

🔍 Over three quarters of cybersecurity professionals did not receive a pay rise last year, and roughly half report feeling undervalued, according to the Harvey Nash Global Tech Talent & Salary Report. Only 45% expect a pay increase in the next 12 months, placing information security professionals among the most pessimistic about pay prospects. Just 22% said their organisations increased cybersecurity resources after high-profile incidents, driving dissatisfaction and turnover risk.
read more →

Be My Eyes AI: Safety for Visually Impaired Users Online

🧑‍🦯 Be My Eyes and its Be My AI feature can help visually impaired users identify on-screen content and even flag phishing attempts, but they are not infallible. In tests, the AI identified fake login pages and suspicious emails, yet risks such as hallucinations and prompt-injection remain. Treat AI output as a first-pass check, avoid sharing confidential details with unknown volunteers, install trusted security software and use a password manager, and prefer apps that process sensitive documents locally when possible.
read more →

Fortinet Training Institute Earns Multiple Industry Awards

🏆 Fortinet’s Training Institute has been honored with multiple industry awards that validate its sustained investment in cybersecurity education and certification. The institute continues to expand the NSE Certification program with role-based pathways and a global ecosystem spanning over 150 countries and 800 academic partners. Fortinet also delivers a SaaS-based Security Awareness and Training service—now offered in an education edition free to primary and secondary schools—and has pledged to train 1 million people by the end of 2026.
read more →

UK Cyber Security Council Adds Associate Professional Title

🔐 The UK Cyber Security Council has launched a new Associate Cyber Security Professional title, with applications open from 13 April to 17 May. The entry-level certification places holders on the UK Cyber Security Professional Register, requiring demonstration of competence across five key areas and a commitment to 75 hours of CPD over three years. Applicants can fast-track if they hold aligned qualifications, and the scheme aims to help early-career candidates prove their readiness to employers.
read more →

Custom Private Training to Reduce Cyber Operational Risk

🔐 Check Point Services offers PS Private Training (Custom ILT), a tailored instructor‑led program that turns complex security environments into operational control. The service replaces generic courses with environment‑specific labs, hands‑on exercises, and field‑proven best practices delivered by active Professional Services consultants. It focuses on closing hands‑on skill gaps, speeding issue resolution, and lowering operational risk even in well‑equipped organizations.
read more →

Internet Bug Bounty Pauses Payouts Amid AI Advances

🛑 The Internet Bug Bounty program, administered by HackerOne and backed by multiple major software companies, has paused submissions and payouts while it reassesses how best to support open source security. HackerOne said the rise of AI-assisted vulnerability discovery has increased both coverage and speed, shifting the balance between new findings and remediation capacity. Projects such as Node.js will continue to accept and triage reports via HackerOne but may not issue rewards from the paused fund. Similar changes have hit other programs, including curl and recent restrictions at Google's open source rewards effort.
read more →

Fortinet Training Institute Announces 2026 ATC Award Winners

📣 Fortinet announced the winners of the 2026 Training Institute Authorized Training Center (ATC) Awards, recognizing partners that excel in delivering NSE certification and hands-on cybersecurity education across more than 150 countries. The awards highlight regional and categorical leaders — from Partner of the Year to Certified Trainer of the Year — for measurable impact in skills development. Fortinet emphasized that structured, role-based training is a core security control as organizations expand teams, mandate certifications, and adapt to AI-influenced threats.
read more →

A Taxonomy of Cognitive Security and Reality Pentesting

🧠 Bruce Schneier highlights K. Melton’s recent framework on cognitive security, cognitive hacking, and “reality pentesting.” Melton organizes cognition into five architectural layers—sensory interface, neurocompiler, mind kernel, the mesh, and cultural substrate—and shows how fast, unconscious processes (Kahneman’s System 1) create exploitable backdoors. The taxonomy frames human perception as an IT-like attack surface and suggests practical implications for testing, defense, and threat modeling.
read more →

Rethinking Human Risk: Awareness Isn't a Control, Period

🔒 Organizations frequently treat security awareness training as a control, but this article contends it is primarily a cultural measure that cannot guarantee consistent outcomes. While training and phishing simulations reduce risk at the margins, they do not eliminate human variability or stop sophisticated business email compromise, credential harvesting, and modern MFA bypass techniques. The author recommends engineering systems to assume human fallibility—through phishing-resistant authentication, enforced financial controls, continuous identity telemetry, and real-time anomaly detection—so a single mistake cannot cause material harm.
read more →

Cybersecurity as a Societal Challenge: Leadership & Education

🔒 In the fourth episode of Season 2 of Brass Tacks - Talking Cybersecurity, Joe Robertson and Professor Richard Benham examine how cybersecurity has shifted from an IT concern to a wider societal challenge that touches public services, national security, education, and everyday life. Benham draws on a career spanning finance, cross‑border policing and public service to show how digital risk became a national priority. He argues that leadership, rethought education and cross‑sector collaboration—illustrated by a pioneering MBA program and the National Cyber Awards—are key to building resilience.
read more →

Hidden Cost of Cybersecurity Specialization and Skills Loss

🔒 Bryan Simon, a SANS Senior Instructor, argues that accelerating specialization in cybersecurity is eroding foundational skills and shared context. When teams focus narrowly on domains or tools, organizations lose end-to-end visibility, risk prioritization weakens, and decisions drift toward product selection instead of mission-driven protection. Simon emphasizes that knowing what is "normal," mapping assets to business impact, and reinforcing core competencies are essential; he will teach these principles in SEC401 at SANS Security West 2026.
read more →

Google adds Advanced Flow for safer APK sideloading

🔒 Google is introducing Advanced Flow, a new Android mechanism that lets power users sideload APKs from unverified developers while adding multi-step protections. The one-time process requires enabling Developer Mode, confirming you are not being coached by a threat actor, restarting and reauthenticating, then waiting one day to validate the changes. After completion users may enable installations for a week or indefinitely, and Android will display a warning that the app is from an unverified developer. The flow is intended to add friction and disrupt urgency-driven scam tactics.
read more →

NCA Chief Warns Teens Are Being Radicalized into Cybercrime

🚨 The head of the UK's National Crime Agency, Graeme Biggar, warned at the launch of the NCA's National Strategic Assessment that online platforms and algorithms are 'radicalizing' teenagers into cybercrime, alongside other harms. He said technology is reshaping crime and that tech companies must take responsibility. Biggar highlighted rising UK-based attackers, surges in online fraud and sextortion, and the creation of the Online Crime Centre to speed data sharing across government and industry.
read more →

Five Ways Google Helps You Avoid Tax Season Scammers

🔒Google outlines five practical defenses to help users spot and avoid tax‑season scams. It describes on‑device AI protections on Pixel phones including Call Screen and optional real‑time Scam Detection alerts, plus text‑vetting with Circle to Search and Lens. The post highlights real‑time Safe Browsing, high‑visibility Gmail warning banners and security steps like Passkeys and 2‑Step Verification to reduce fraud risk.
read more →